|
|
Why Are You Getting This?
You signed up to receive The Privacy Professor Tips, or initiated contact to stay in touch with Rebecca and/or Privacy & Security Brainiacs (PSB) and consented to receive the Tips. Please read our Privacy Notice & Communication Info at the bottom of this message for more information. You may unsubscribe from there as well.
NOTE! For those of you who requested or agreed to receive the Tips over the past 12 months: We recently learned that you did NOT receive any of our Tips during the past 12 months due to an omission in our distribution list settings! So those of you just now receiving the Tips after not receiving them over the months, this is why. We apologize
for any confusion this caused.
| | |
Image © from Rebecca Herold; all rights reserved.
Halloween 2007 with my sons. An adorable Neo (Keanu Reeves) from the Matrix, and the Grim Reaper. Hopefully it is apparent who I am. ("I'll get you my pretty!")
| | Nightmare on Data Street: Privacy Scares That Follow Death | | |
It's a spooky time of year, folks. All manner of ghoulish tricksters and treaters are donning disguises designed to fool even the most whip-smart among us.
But it's not just Halloween time that brings out the disingenuous, and frights are emerging from pretend graves. More and more, personal information and legacies are being co-opted for not only criminal use by others, but also to feed into new technologies such as AI. Or, at great and growing concern to many others, to “create” people again to “speak to” and “give their wise advice” after they have actually passed from this world.
As our world becomes increasingly digital, it's easier for not only people to pretend to be you, but also for digital pieces of you left behind to be used for others’ benefit and financial profit. These activities can then potentially harm your surviving friends and family. In addition to changing your legacy, and what you actually did, or did not do, while you were alive, which can also harm others. Let's take a look at a few of the ways that privacy after death situations might be tricks with no treats this month and beyond...
| | |
This month we’ve included some great reader questions covering our privacy after death topic, three healthcare and HIPAA topics, the impact of quantum computing on password security, and cybersecurity tools that every MSP and IT provider needs.
Please read to the end where we provide some information about our recent activities and online courses.
Since 2005, we have been freely distributing the Privacy Professor Tips monthly publication to help both businesses and individuals, of all ages, identify risks throughout their daily lives, within their own businesses, and to help them know how to prevent security incidents, privacy breaches, and to keep from being a victim of scams.
By sharing this Tips issue with others in your organization, you are also supporting a wide range of regulatory and other legal compliance requirements to sending such awareness communications. Thank you for reading and sharing!
| | |
We would love to hear from you!
Did you find the tips we provided useful? Did you like this issue? Do you have questions for us to answer? Please let us know at info@privacysecuritybrainiacs.com.
| | Image created by Rebecca Herold on FreePik. | | |
October Tips of the Month
- News You May Have Missed
- Privacy & Security Questions and Tips
- Where to Find the Privacy Professor
| | |
We are finding more unique news stories to share with you than ever before. We also share news items that we believe are important for most folks to know, but that often do not get much mention in traditional news, or even in security and privacy news outlets.
Here are just a few of the 100+ news stories we discovered throughout the past month that provide a wide range of interesting security and privacy related news. These news items demonstrate that such types of risks exist basically anywhere in the world, and that everyone needs awareness.
This month we list 40 news items. We are grouping them into four broad categories: The first is for this month’s topic of “Privacy after death,” followed by “Of broad interest,” “Privacy in businesses, governments, and other organizations,” and “Laws, legal issues, and lawsuits about or significantly involving privacy and/or security issues.” Many readers will find all the items of interest, but for those of you who prefer one or two specific categories, this will help you find your news items of interest more quickly. Within each category the items are in no particular order. By popular request are also now including “INSIGHTS” with many of the situations to provide some advice or additional insights. Thanks to those many readers who sent your positive feedback; we appreciate it!
Do you have interesting, unusual, bizarre or odd stories involving security and privacy? Some of the most interesting, bizarre or odd stories are in local news! Or questions about any of the notes we included for the stories we listed this month? Let us know!
| | Specific to Privacy After Death | | |
A growing number of criminals, AI bots, and other ghouls are clamoring for the data of the deceased. And for those who are still living, false claims of their deaths create turmoil and trepidation. Here are 10 representative news reports from this year.
1. Quebec Woman Mistakenly Declared Dead Fights To Prove She’s Alive. “Since her father Vasilios Daskalopoulos died on July 12, Ourania “Nia” Daskalopoulos has been drowning in paperwork.” She was his caregiver over the last five years of his life and in charge of his estate. She found out an error occurred when the funeral home mistakenly put her driver’s license number on her father’s declaration of death form/certificate. INSIGHTS: This highlights the need for every business, including funeral homes, to have procedures in place to not only provide security for access to death records, but also to ensure the accuracy/integrity of the data that they put in the death certificates and other related documents. Lack of such procedures can significantly disrupt and cause huge problems, such as in this situation, which will now possibly impact Nia’s children when she dies. Too many organizations, throughout all industries, do not include information integrity procedures within their security programs.
2. Canadian Woman Says She Lost Her Pension And SIN After CRA Mistakenly Declared Her Dead. 'Now I have no income, no access to support, and just $7 to my name,' the 65-year-old from Vancouver posted online when the issue was ongoing. A CRA spokesperson “said, situations like these could happen for a variety of reasons, such as human error, a miscommunication from another government department, or an error made when a return is filed on behalf of a deceased person.” INSIGHTS: Similar to the previous news item. There need to be checks to validate data accuracy and integrity prior to declaring deaths and cutting off benefits.
| | |
3. Legal Resurrection If You're Mistakenly Declared Dead. “In most cases, this is caused by a simple clerical error at the U.S. Social Security Administration (SSA). In 2011, an audit estimated that about a thousand people per month were declared legally dead.” This number is estimated to be much higher now. INSIGHTS: Why are so many of these errors occurring? Are audits being done to identify where the vulnerabilities are allowing for such distressful problems? They should be. Along with then identifying ways to prevent them from happening. Starting with increased security and privacy training to the associated workforce members, and training software coders and developers to do better, and perform more comprehensive testing.
4. ‘Dead’ California Mother Is Very Much Alive, Family Says. “It is unclear exactly how she was declared dead — computer glitch? human error? — but the mix up has been near-catastrophic for the stroke survivor, who has been purged from Medicare and health insurance systems. She also had her bank and credit cards canceled, and years’ worth of her pension payments were pulled away overnight.” INSIGHTS: See the previous news item, which are also applicable here.
5. Wrongly Declared Dead, 83-Year-Old In Wisconsin Tries To Revive Social Security Status. An 83-year-old Kenosha woman was mistakenly declared dead by the Social Security Administration (SSA) 6 months following the death of her husband. A declined Medicare payment first alerted the family to the issue. The woman's daughter says they spent hours on hold with SSA trying to resurrect her vital status. The Social Security Administration had not only had only had marked her husband as 'deceased' but then had marked her as 'deceased'. INSIGHTS: These many situations happening this year share many similarities, based on news reports. We found over 20 (we stopped counting after passing that mark) more similar situations reported since the beginning of this year.
6. Obituary Scams. Scammers are calling family members claiming the deceased left an outstanding debt that must be paid immediately.
7. Law Professor: Let Bereaved Families Delete Data To Stop AI ‘Digital Resurrection’. Legal scholar Victoria Haneman is arguing that dead people’s estates should have the right to digital deletion—to protect against 'digital resurrection' and give them 'the right to be dead.' “The issue of “digital resurrection” is definitely picking up more attention in the mainstream. In an interview with Rolling Stone, Hollywood star Samuel L. Jackson told future actors to cross out the “in perpetuity” clauses in their contracts when discussing how actors may now be asked to submit complete digital scans of their faces and bodies.” INSIGHTS: It is prudent for everyone to start including similar types of legal clauses in contracts where personal data is being collected and/or derived, processed, shared and used.
8. The OpenID Foundation’s Death and the Digital Estate (DADE) Community Group is building mechanisms to ensure continued access to an individual’s data after death to allow people’s descendants and future historians to understand this present moment in time, with people’s physical and metaphorical aspects captured and preserved in high resolution permanent digital storage. AI systems connected to these data stores massively expand the capabilities and risks of such digital perpetuity. INSIGHTS: Obtain consent from living individuals to allow for this after they die. Also, think about what you would, and would not, want others to use of your personal data, ideas, work, etc. after you die, in possibly any way. Most people would allow for some specific uses, but would not give carte blanche to do just anything with their personal data, and other data associated with their lives.
9. Organized Insurance Claim Fraud Is Exploiting Identities Of Deceased/Terminally Ill People. An insurance fraud racket was uncovered in India where fabricated documents, including Aadhaar and other IDs, were used to file false death claims and other scams using identities of deceased or vulnerable people. This prompted government/private ID cleanup efforts.
10. How 5 Influential People Responded to False Reports of Their Death. As Mark Twain said: “The report of my death was an exaggeration.” On finding out he had been pronounced dead, a farmer from Uttar Pradesh, India, fought for almost 20 years to prove he was alive. His fight revealed serious weaknesses in India’s bureaucratic systems.
| | 11. Hackers Contact Harrods After 430,000 Customer Records Hit By IT Breach. Luxury department store Harrods has been contacted by hackers after data relating to 430,000 customer records was stolen in an IT breach. The stolen data included basic personal information, including names and contact details if they had been provided. Some information relating to marketing preferences, loyalty cards and tie-ins to other companies was also taken, including Harrods co-branded cards. | | 12. London Nurseries Hit By Hackers, Data On 8,000 Children Stolen. Cybercriminals have stolen data on over 8,000 children attending nurseries in London operated by childcare provider Kido International, the hackers said on their dark web portal. The gang, which calls itself Radiant, evidenced its claim by publishing the names, photos, home addresses, and family contact information of 10 children it said attended one of Kido's 18 nurseries in Greater London. | | Initial image created by Rebecca Herold using Google Gemini. Included to show how AI generated photos often include errors or images depicting scenes that would not be found in real life upon first creation. It could have been made more realistic with multiple additional iterations of changes. | |
13. Georgia Men Sentenced For Running Scam Out Of Prison Targeting Iowans. Court documents show between March 2022 and April 2024, Russell Weatherspoon, Karl Dieudonne, Demonte Brazil, and Gregory Scorza ran a fraud scheme across multiple states, including Iowa. Investigators say the scammers led victims to believe a warrant for their arrest had been issued for failing to appear in court. The victims were told they would be arrested if a cash bond was not posted. They were then directed to a bond company or other locations to meet and pay a bond for failing to appear as an expert witness as required by a subpoena. Prosecutors say Weatherspoon led the scam from a prison in Georgia. A drone was used to fly over the prison and drop cell phones into the yard where the inmates were able to pick them up and use them to carry out the scam calls. INSIGHTS: This demonstrates how IoT devices, such as drones, are now being used to surreptitiously commit a wide variety of break-ins, and other types of crimes. Having security and privacy policies and procedures to protect against such interlopers could prevent these types of situations.
14. The Minnesota Department of Revenue is warning about a scam text message targeting Minnesotans. Fake text messages claiming to be from the department are asking people to click on a suspicious hyperlink to update their banking information and claim a refund. State officials stress the text messages are not from the Department of Revenue and that the department will never send unsolicited texts to Minnesotans. Minnesotans receiving these scam texts should:
a. Refrain from clicking the hyperlink in the text
b. Report the text as junk/spam on their phone and delete it
c. Contact their bank if they clicked the link and input their information
15. Iowa’s Winneshiek County Sheriff’s Office Is Warning The Community About A Fraudulent Check Cashing Scam. The sheriff’s office says they have received multiple reports of fraud involving payment checks sent through the mail. In this scam, the scammer steals a check from the mail (public mailboxes, residential mailboxes, etc.), forges it, rewrites the payment amount to make it larger, and then cashes it. Authorities said this scam has been frequently seen for payments made to credit card companies.
| | |
16. Reported In Britain, Women Are Now Just As Likely As Men To Be Targeted By Criminals In Sophisticated Investment Scams, Surrey Police Has Said. Operation Signature lead, PC Bernadette Lawrie told Radio Surrey that historically, pension-age males were the "typical demographic" scammers targeted with investments in diamonds, fine wines, stocks and shares. However, she said fraudsters were "moving away" from traditional investments and targeting people through cryptocurrency or online-based platforms. "It's anyone from ages 30 to 80, and both genders being approached on social media," PC Lawrie said.
17. From Mason City, Iowa: “Scammers are calling local residents and giving the name of a current Mason City Police Officer in an effort to obtain your personal information. They will provide a callback number that isn't a MCPD business line. Please hang up and know it isn't your MCPD calling!”
18. FBI Boston Warns Of Rise In 'Cruel' Courier Cash Scams In New England. More than $26 million from 2023 to May of this year was stolen primarily from elderly residents throughout New England in a rising tide of reports of fraudulent couriers collecting bulk cash or gold bars that have resulted in "devastating" financial losses, according to officials at the Boston division office of the U.S. Federal Bureau of Investigation.
19. Man Falls Into AI Psychosis, Kills His Mother and Himself. Horror beyond words. A 56-year-old man named Stein-Erik Soelberg was a longtime tech industry worker who’d moved in with his 83-year-old mother. “Soelberg called ChatGPT “Bobby Zenith.” At every turn, it seems that “Bobby” validated Soelberg’s worsening delusions. Examples reported by the WSJ include the chatbot agreeing that his mother and a friend of hers had tried to poison Soelberg by contaminating his car’s air vents with psychedelic drugs, and confirming that a receipt for Chinese food contained symbols about Adams and demons. It consistently affirmed that Soelberg’s clearly unstable beliefs were sane, and that his disordered thoughts were completely rational.”
| | Privacy In Businesses, Governments, And Other Organizations… | |
21. AI Just Created A Working Virus. The U.S. isn’t prepared for that. A stunning scientific accomplishment brings both great promise and great risk. “AI created novel viral genomes, which the researchers then built and tested on a harmless strain of E. coli. Many of them worked. Some were even stronger than their natural counterparts, and several succeeded in killing bacteria that had evolved resistance to natural bacteriophages. The scientists proceeded with appropriate caution. They limited their work to viruses that can’t infect humans and ran experiments under strict safety rules. But the essential fact is hard to ignore: Computers can now invent viable — even potent — viruses.”
22. Microsoft Fires Four Workers Over Protests Against Firm’s Ties To Israel. Microsoft says the terminations followed serious breaches of company policies amid claims that its software is used by Israeli army in Gaza.
23. Nationwide Ring Used Fake Warrants, Bogus Bond Companies To Scam Iowans, Prosecutors Say. According to the federal indictment filed in June 2024, victims — nearly all employed in the medical profession — were falsely told that arrest warrants had been issued for failing to appear as expert witnesses in court.
| |
24. Google Has Issued A Global Security Alert Advising Its 2.5 Billion Gmail Users To Update Their Passwords Following A Data Breach Involving One Of Its Salesforce Databases. The incident has triggered an aggressive wave of phishing and impersonation attacks targeting users across the platform.
25. UK ‘Agreed To Drop’ Apple Data Demand In Privacy Row, US Chief Says. The UK agreed to drop its mandate for Apple to provide a ‘back door’ that would have enabled access to the protected encrypted data of American citizens and would have violated civil liberties.
26. Sherrill Decries National Archives Leak Of Her Private Info In Military Records. “An apparent National Archives and Records Administration error has resulted in the unredacted leak of the naval records of gubernatorial candidate and U.S. Rep. Mikie Sherrill, D-New Jersey.” CBS News, which first reported on the release, said the record disclosure potentially violates the Privacy Act of 1974 as well as exemptions established under the Freedom of Information Act.
| |
27. Facial Emotion Recognition in the Future of Work: Social Implications and Policy Recommendations. “The article considers how employers would use employee facial emotion data for data-driven decision-making in, for example, the construction and optimization of virtual teams, appropriateness for promotion to leadership positions, and fitness-to-task in mission critical work.” INSIGHTS: This may require a subscription.
28. App Built To Report Kirk’s Critics Outs Its Own Users. An app and website founded by conservative activist was exposing personal data about its users. A researcher identifying himself as BobDaHacker uncovered a flaw that exposed user emails and phone numbers, even if privacy settings were switched on. INSIGHTS: This is another example of the need to thoroughly test security and privacy comprehensively in software before making it available to the public.
29. U.S. Government Scrambles To Stop New Hacking Campaign Blamed On China. Officials warned that the breaches since May allowed hackers to remain inside Cisco security gear deployed to protect government networks.
30. Fitting Rooms In The Cloud: Privacy Implications Of VTO In Retail. As retailers increasingly adopt artificial intelligence (“AI”) to enhance digital shopping journeys, virtual try-on (“VTO”) technology offers a compelling combination of convenience, personalization, and engagement. However, this innovation also raises complex data protection questions that are too often overlooked in the pursuit of frictionless consumer experiences. VTO solutions rely on processing a wide range of personal data, often including biometric data raising complex compliance issues under the UK GDPR and related data protection laws.
| | Laws, Legal Issues, And Lawsuits About Or Significantly Involving Privacy And/Or Security Issues… | | |
32. Enforcement of Colorado AI Act Delayed Until June 2026. The delay does not alter the core framework enacted in 2024. Unless amended further in the regular legislative session in the Spring, the law will impose duties on both developers and deployers of high-risk AI systems as of the new date.
33. Jaguar Land Rover to Bear Full Cost of Cyberattack Due to Lack of Insurance Cover. JLR had been negotiating a policy through broker Lockton but had not finalized the deal. As a result, the company is believed to lack direct coverage for what has quickly become one of the most disruptive cyber events to hit the U.K. manufacturing sector.
34. Beijing Internet Court Requires Evidence of Creative Effort to Claim Copyright Protection in AI-Generated Images. On September 16, 2025, the Beijing Internet Court announced a recently upheld decision in which they held that while copyright can exist in AI-generated images, the author must “demonstrate that they have exerted creative effort in their AI-generated creations, reflecting personalized expression…When asserting rights in AI-generated works, authors are obligated to explain their creative thinking, the content of their input commands, and the process of selecting and modifying the generated content, and to submit relevant evidence.”
35. Medusind, a vendor of revenue cycle and practice management software, will pay $5 million to settle a class action stemming from a 2023 data breach that exposed personal and protected health information of more than 701,000 people. The company did not admit to any fault or liability but did agree to establish a settlement fund and improve security. On or around December 29, 2023, the firm identified unauthorized access to its computer systems and found evidence to suggest that files had been exfiltrated from its network. The file review confirmed that more than 701,000 individuals had protected health information exposed in the incident, including names, contact information, health insurance information, medical histories, driver’s license numbers, passport numbers, and Social Security numbers. Notification letters were mailed to the affected individuals more than a year after the intrusion was detected.
36. In California, lawmakers passed SB 53, the nation’s first comprehensive AI transparency law for frontier models, now awaiting Governor Newsom’s signature. On September 29, Governor Newsom signed the bill, enacting it into law. It will require major AI developers to publish risk frameworks, transparency reports, and safety incident disclosures beginning in 2026—marking a shift from the heavy mandates of last year’s vetoed bill.
37. California Passes “No Robo Bosses” Act – With September 30 Deadline for Governor Action. California lawmakers have taken a significant step forward in regulating the use of AI in the workplace by passing SB 7, a bill aptly referred to as the “No Robo Bosses” Act. If Governor Newsom signs the bill into law—a decision he must make by September 30, 2025—SB 7 would take effect on January 1, 2026, and would have an immediate impact, including prohibiting employers from relying solely on AI to make decisions regarding employee discipline or termination.
38. Justice Department Says It’s Suing Oregon And Maine As It Seeks Voter Data In Multiple States. The Justice Department said Tuesday that it has sued Oregon and Maine for failing to turn over their voter registration lists, marking the first lawsuits the department has brought against states in its wide-ranging effort to get detailed voter data. The department said the states were violating federal law by refusing to provide electronic copies of state voter registration lists and information regarding ineligible voters. Oregon and Maine are among at least 26 states that the department has asked for voter registration rolls in recent months, according to an Associated Press tally. Several states have sent redacted versions of their voter lists that are available to the public, but the Justice Department has on multiple occasions expressly demanded copies that contain personally identifiable information, including voter names, birth dates, addresses and driver’s license numbers or partial Social Security numbers. The Justice Department’s outreach has raised alarm among some election officials because the agency doesn’t have the constitutional authority to run elections. That power is granted to states and Congress. Federal law also protects the sharing of individual data with the federal government.
39. EFF, ACLU to SFPD: Stop Illegally Sharing Data With ICE and Anti-Abortion States. The San Francisco Police Department is the latest California law enforcement agency to get caught sharing automated license plate reader (ALPR) data with out-of-state and federal agencies. EFF and the ACLU of Northern California are calling them out for this direct violation of California law, which has put every driver in the city at risk and is especially dangerous for immigrants, abortion seekers, and other targets of the federal government.
40. A federal judge has granted preliminary approval to a proposed settlement requiring Google to pay $30 million to resolve class-action claims that it violated children's privacy by tracking their YouTube activity in order to serve targeted ads.
| | Check out our Privacy & Security Brainiacs blog page for more unique security and privacy news items. Have you run across any surprising, odd, offbeat or bizarre security and/or privacy news? Please let us know! We may include it in an upcoming issue. | | |
Privacy & Security Questions and Tips
Rebecca answers hot-topic questions from Tips readers
October 2025
| | |
We continue to receive a wide variety of questions about security and privacy. Questions about current hot topics in society, and increasingly more about healthcare privacy and security. Thank you for sending them in! This month in addition to our Question of the Month about putting privacy protections within wills, we’ve included five additional questions about privacy protections after death under HIPAA, impacts of quantum computing on password security, and security tools every IT provider and Managed Services Provider (MSP) needs.
Are the answers interesting and/or useful to you? Please let us know! Keep your questions coming!
| | Q1: What should a person include in their will to protect themselves and their survivors after their death from crimes, legacy changes, and other types of privacy harms and security risks? | | |
A1:
This is not only a thoughtful, forward-looking question, but also one that is very important to consider and then act upon. It is an increasing trend for people to include “privacy preservation,” “personal data legacy,” or similarly titled clauses within their will and estate plans. Including these actions and wishes within wills and estate plans will reduce the risks of identity theft and fraud. It can also help to prevent having the history or their lives changed to be different than what actually happened, which can impact and harm the survivors (family, significant others, friends, co-workers, etc.) of the deceased.
Such clauses can also help to ensure use, including misuse, of the deceased’s data or likeness after death does not occur. Think about it. Would you like to have others, including strangers, putting words and opinions in your mouth that you would never have said or even vehemently disagree with? Consider how people have already started using AI to create videos of the deceased to represent what those who have died would say or think about certain situations or news. Would you want strangers and/or AI to put such words and opinions in your mouth, about topics you may have never even heard of before death?
Here are some key actions to take, and directives to include in your will and other types of estate plans, to help protect your and your survivors:
(1) Appoint a personal data and digital executor. This should be someone you trust, who you also will need to give authority to for managing all your accounts, digital processing and storage devices, and data in all forms. Document the authorities and actions you want to give them the responsibilities to enact.
(2) Document, and secure, an inventory of physical and digital assets, particularly of personal information. Include information for your email, social media, apps, login credentials (banks, credit cards, insurance, etc.), cloud storage services (e.g., photos, videos, etc.), domain names, crypto wallets, photo archives, subscription services, and any other type of product or service where you have information or other types of assets stored.
(3) Strongly secure and store all the directives, security credentials (IDs and passwords), and other types of important access control and assets information. Document if you want such accounts to be deleted, transferred (to the executor, specific family members or friends, etc.), and/or used as part of your life memorialization.
(4) Provide clear, comprehensive information (in all forms) deletion and memorialization instructions. Include explicit clauses covering what you allow, and do not allow, to be used to represent you, your thoughts, likenesses, etc., using AI tools, in articles, photos and videos, and use of your wide range of personal data.
- For example, “I do not consent to my personal data, writings, recordings, or likeness being used to train or fine-tune artificial intelligence systems.” Some social media sites provide people, generally outside of the U.S., with the ability to indicate this in their account settings.
- Regarding the use of AI clones of you, include statements similar to, “I do not consent to having my image, voice, or any other aspect of my being of being used to create avatars, chatbots, or other types of clones of me, my views, or any other representation of who I am, how I think, etc.” Edit to reflect your personal choices.
- Regarding the use of your image, name, or voice, indicate if you want to forbid such use, or do not allow it without your executor’s or specific family’s consent.
- Include whether or not you allow a person's heirs or estate to control and profit from your name, likeness, and other identifying attributes for commercial purposes after your death; such rights are generally considered property assets that can be passed on to descendants in some states in the U.S., and in other countries. The U.S. currently does not have a federal right of publicity for such use of deceased individuals for commercial purposes.
- Document whether you want online memorials, websites, or your social media accounts preserved as part of your legacy.
(5) Provide details and directions for the fraud-prevention actions and associated steps you ask your survivors to take after your death.
- Direct your executor to notify the credit bureaus and set death alerts on your accounts, and freeze your credit reports, notify government agencies (e.g., Social Security (U.S.)/tax authorities; pension funds; etc.) and insurers of your death to help prevent benefits misuse.
- Provide instructions for irreversibly destroying, or strongly encrypting if destruction is not an option, of private files if you don’t want them preserved.
- Instruct the executor to review your devices/accounts for sensitive data that could harm living relatives (medical files, correspondence, images, videos, etc.), and whether to secure or delete each of them appropriately.
(6) Provide directions for submitting claims to life insurance policies, and closing bank accounts when they are no longer needed (e.g., after accounts have stopped being used for auto pay, etc.), such as for mortgages, credit cards, loans, and unused IDs. Some accounts may need to continue to be used while the executor sorts out the deceased’s outstanding debts, long-term commitments, plans for others to take over each specific account, etc.
(7) Authorize the executor and/or specific individuals to pursue legal or administrative remedies if your identity is misused posthumously.
(8) I have some friends who are probate and estate planning attorneys, and they all recommend including a statement similar to the following catch-all clause: “My digital executor has the authority to access, control, delete, transfer, or restrict use of all my information assets (physical, digital, and other forms), accounts, and personal data, to the maximum extent permitted by law, in order to protect my estate, privacy, legacy, and the rights of my survivors.”
(9) Review the actions and information above with those who you want to execute your wishes.
Here are a few final tips related to the above:
- Don’t document your passwords or other types of authenticators within the will itself; probate records are made public in some locations so doing so could cause huge privacy problems and other legal catastrophes.
- Review your local laws to verify the rights of executors, including over digital assets.
- Update your will regularly; at least once a year. Why? Technologies change often. New technologies emerge continuously. Business accounts often change. Laws can change quickly, and new ones emerge.
- I highly recommend you engage a probate and/or estate planning lawyer. Not only they can ensure your language is enforceable in your applicable jurisdiction, but they can also provide expert guidance and opinions for challenges to your will, and also in court in the event such challenges go that far.
| | |
(Somewhat) Quick Hits:
Here are five more questions, most of which we are answering at a comparatively high level. We provide more in-depth information and associated details about these topics in separate blog posts, videos on our YouTube channel, in infographics and e-books, LinkedIn posts to our business page, and within our online training and awareness courses.
| | |
Q2: Do the HIPAA protections apply to the health information of deceased individuals?
A2:
Yes. HIPAA protects the health information that U.S. healthcare providers, insurers, and clearinghouses (collectively called covered entities, or CEs for short) possess and have access to for a period of 50 years following the date of death of the associated individuals. Both the CEs and their business associates (BAs) must protect such health data during this period of time to the same extent that HIPAA protects the health information of living individuals. I want to emphasize the fact that BAs are also responsible for the security and privacy of the health data they have access to for that 50-year period. There has been a trend in recent years of BAs monetizing the health data of the deceased, such as selling it to AI vendors. This is a violation of HIPAA.
| | Q3: I own a small specialty healthcare research lab, which also provides care to cancer patients. I learned from your Privacy & Security Brainiacs HIPAA course that HIPAA protects a deceased person’s health information for 50 years following the individual’s death. Does this mean I am required to keep the decedent’s information for that period of time? | | |
A3:
No, HIPAA does not require CEs to retain patients’ health records for 50 years. But if they do, such as for research work, then you must comply with all the HIPAA requirements for the deceased’s records.
HIPAA does not include general medical record retention requirements beyond the 6 years of retention that applies to all types of documentation and other information that is covered by HIPAA. Covered entities may destroy patient records after that time under HIPAA. However, make sure you check for all other local, state, federal and contractual legal requirements for other retention obligations for which you may need to comply.
| | |
Q4: I am the son and appointed executor of my recently departed father’s estate. I want to obtain all his health records. I’ve requested them twice from the EMS and three of his other healthcare providers. At first, they all indicated they would provide them. However, now they are all using HIPAA as a reason for withholding my father’s health records. Does HIPAA prohibit access to a recently deceased family member’s health records? Or, to an executor of the estate of a recently deceased individual? If so, what do you recommend?
A4:
My sincere condolences for your loss.
No, HIPAA does not prohibit family members access to the health records of their deceased family members. Quite the opposite!
During the 50-year period requiring protection of decedents’ health records, the personal representative (e.g., the executor of the deceased’s estate), and others who were explicitly given access to the decedent have the legal rights under HIPAA with regard to the decedent’s health information, such as authorizing certain uses and disclosures of, and gaining access to, the information, in compliance with 45 CFR 164.524(a) and 45 CFR 164.502(g).
HIPAA also permits a covered entity (CE) to disclose PHI about a decedent to a family member, or other person who was involved in the individual’s health care or payment for care prior to the individual’s death, unless doing so is inconsistent with any prior expressed preference of the deceased individual that is known to the covered entity. This may include disclosures to spouses, parents, children, domestic partners, other relatives, or friends of the decedent, provided the information disclosed is limited to that which is relevant to the person’s involvement in the decedent’s care or payment for care. Such access persists after the patient’s death.
I recommend you discuss this with your lawyer. It is likely that part of the actions your lawyer will recommend will include creating and sending to each of the healthcare providers a letter to request medical records which is a right that HIPAA provides to individuals, and their representatives. Such records must be provided to you within 30 days. One 30-day extension may be allowed (for a maximum total of 60 days), but only if the healthcare provider provides you with notice during the initial 30 days, explaining why they cannot get the records to you within 30 days.
It is important to note that HIPAA does not require such a written request from a personal representative such as those described earlier; a verbal and/or in-person request from a personal representative is sufficient.
| | |
Q5: Quantum computing could render today’s password encryption useless in the near future. How should MSPs prepare their clients for the potential impact of quantum computing?
A5:
Important question! While quantum computing is not saturating the online discussions right now (AI is stealing all the attention at the moment), it will soon be used widely, and catching most organizations off-guard. The time to act is now. IT providers, and MSPs generally, can provide a great service to their clients by helping them be prepared for the impacts of quantum computing, starting with password encryption.
For example, consider quantum computers using Shor's algorithm, which can factor large numbers and solve discrete logarithms exponentially faster than classical computers. Very beneficial for organizations of all types doing a wide range of computations that have historically been impossible to use for most purposes. However, as with most technologies, great benefits also come with great risks if those risks are not thoughtfully and effectively mitigated. Shor’s algorithmic capabilities make it a threat to public-key encryption systems like RSA and ECC, which basically rely on the computational difficulty of these associated mathematical problems. Shor’s algorithm doesn't perform encryption or hashing itself, which is one of the reasons why many strong proponents of quantum computing poo-pooh the password-cracking risk possibilities. However, in addition to the benefits, Shor’s algorithm also compromises the security of existing public-key encryption systems, like RSA and ECC, which rely on the computational difficulty of these mathematical problems. In other words, quantum computing basically breaks the mathematical foundations of those encryption systems, making it able to break the public-key cryptography that secures password transmissions (e.g., TLS/SSL), password hashing functions, and authentication protocols. This would then result in making passwords sent over networks, stored password hashes, and multi-factor authentication systems all vulnerable with how encryption is currently used for those purposes.
Here is a high-level list of actions to take now, and to use to thoughtfully prepare for when quantum computing infiltrates an organization’s digital ecosystem:
1) Identify and inventory all the passwords, and other types of authentications, related cryptography being used.
2) Determine, and document, how systems can be designed to most easily and efficiently swap out the currently cryptographic algorithms without the need to make major systems engineering changes.
3) Identify quantum-computing-resistant password hashing functions to transition to from those identified cryptographic algorithms. Then make a plan for how to upgrade efficiently with minimal (if any) disruption to business processing to those strong password hashing functions.
4) Identify alternative authentication methods. For example, implementing hardware security keys using post-quantum algorithms and biometric systems that don't rely on vulnerable primitive cryptographic algorithms.
| | |
Q6: I have an IT provider business serving businesses and individual clients in my state. What are some advanced cybersecurity tools that every IT provider needs?
A6:
A very important question! Too many IT providers, as well as managed service providers (MSPs), try to get by with the least possible tools, instead of using the most beneficial and forward-looking tools, that will set them apart from their competitors. Another worrisome trend is turning to untested and often faulty, erroneous, and unsecure AI tools that were created with the primary goal of being money generators instead of being accurate, beneficial and compliant for the users.
With these considerations in mind, here are 6 advanced security tools that every IT provider needs. I’m interpreting “advanced” to mean those tools that most IT providers don’t feel the need to offer since they either are not explicitly legally required for compliance purposes, or because they don’t want to invest in tools that they clients haven’t explicitly requested. Guess what? The overwhelming number of IT providers’ clients aren’t security and privacy experts; IT providers need to have the understanding of why these tools are important to be able to explain to IT provider clients why they are needed.
I could have provided ten times more, but if IT providers would at least do these few, it would improve the security, along with privacy and compliance, of their clients’ digital ecosystems greatly.
1) Strong encryption and cryptographic hash functions. Too many use weak and easily broken encryption (e.g., 56-bit key DES; 3DES; RC4; WEP; WPA2; older SSL and TLS; etc.). Don’t put your clients at unnecessary risk, and likely in noncompliance with privacy and data protection legal requirements by using weak encryption. And many hashing algorithms, e.g., MD5, often used in security applications, have been shown to be weak. For example, some produce the same hash values multiple times (collisions), or can be reverse engineered; yikes! This not only puts the associated IT providers’ clients at legal jeopardy for resulting breaches and non-compliance, it also puts the IT providers themselves at risk since they were the ones who implemented it. A couple of top contenders (out of many others you can consider) for strong hash algorithms include SHA-3, and for passwords, Argon2.
2) Software testing tools. After 40+ years in my career, with the first several years as a systems engineer building corporate applications, testing has not only been generally disregarded or not thoroughly performed, but it is getting worse as software and the networks they are running on become more complex. I’ve seen a plethora of new AI tools being rushed to market to “replace” human software testing activities, or some contracted programmers hired to do coding using them instead of doing any testing themselves. Keep in mind context of use must be considered (along with hundreds of other factors) to thoroughly test software. Make sure you use a software testing tool that has, itself, been thoroughly tested, and that allows the associated IT provider (programmer, developer, coder, etc.) to customize it, and to still do additional human testing to ensure comprehensiveness.
3) Centralized log analysis, threat detection, and automated incident response capabilities. There are many solutions for these types of activities. E.g., Splunk, MS Sentinel, etc. With continuously emerging threats, these are a must to help protect your clients and mitigate the likelihood of allowing them to be victims of attacks.
4) Other network security monitoring tools. IT providers, often at the grumping of their clients (which are often hard to overcome, I know), try doing the minimum they can “get away with” when it comes to such tools. However, when subsequent security incidents and privacy breaches occur, they then ask their IT provider / MSP, “Why didn’t you use these tools?”
5) Automated software update tools. Most IT providers use the application vendor’s free software update methods to update software, which is definitely better than doing nothing. However, even with these free (well, included with the software package that was purchased) tools, there are still vulnerabilities that have led to security incidents and privacy breaches.
6) Increased security, privacy and compliance education. These go beyond giving one poorly designed (non-pedagogically-based) training course to employees when they start work at an organization. Or, giving the same non-effective training course year-after-year, with no updates. Add to this not testing the learners’ understanding, or giving some poor excuse of a quiz that was not designed to provide diagnostic, formative and summative assessment of the learners’ understanding, but instead are designed to simply make the correct answer glaringly obvious to those taking the quiz. Bad security and privacy training results in uninformed and unaware workforce members, that will lead to security incidents and privacy breaches. Needed in addition to annual education with effective training are additional training for subsets of workforce members for specific topics (e.g., to the IT team responsible for the authentication systems), and ongoing reminders and activities to reinforce security and privacy concepts to workforce members to help them incorporate security and privacy protections into their daily work activities. These actions will reduce privacy breaches and security incidents, will demonstrate due diligence, and will support many compliance requirements. My organization provides such online training and ongoing reminders, and I love it when my clients give me feedback on how much they learned. Recently a couple of different clients told me that our courses’ quizzes are harder than what they were used to with previous security and privacy courses. They liked that ours actually make them think about how to apply the lessons learned to related situations in their own organizations, which then make them remember those issues much better, and longer, than in the previous training they had used. Making their workforce members a security strength within their organizations instead of unknowing security risks.
| | Send us any questions you have. And, keep reading the monthly Privacy Professor Tips! | | |
We will soon be publishing three new courses! Our clients are telling us our courses contain more valuable information, real-life use cases and examples, and supplemental materials that they continue to use to support their business after training, than any of the other HIPAA security and privacy courses they have seen or used. Check it out!
We are also excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for some such organizations. Get in touch with us for the details!
Here are some security and privacy gifts for you to consider in our 11-page “Privacy and Security Gifts” guide.
What topics would you like to see us create videos, and more formal online courses, for? Let us know!
Have questions about our education offerings? Contact us!
| | Where to Find The Privacy Professor | | |
Rebecca’s image included in the previously referenced article.
| | |
I had several readers contact us about this article from last year, which is currently circulating on various social media sites again, so we’re including it here. Rebecca was named, “Women Know Cyber: 150 Fascinating Females Fighting Cybercrime.”
| | Rebecca was featured in The Fast Mode’s special edition eBook, 'The GenAI Leap: How Networks Are Reinventing Themselves'. The eBook explores insights and predictions from 75 leading players in the data and connectivity space on how GenAI is transforming telecom and enterprise networks, from managing network performance to enhancing customer experience, mitigating threats and fraud, and improving efficiency. Rebecca’s article is, “Use of AI in Healthcare in 2025: Medical Miracle, or Medical Malpractice?” | | Rebecca’s image included in the previously referenced article. | | Rebecca is happy to be teaching Cybersecurity & Privacy Basics for Engineers and Technical Professionals. Online / Jan 30, 2026 / Course Code: 0105-WEB26. Time: 12:00 PM - 2:00 PM Eastern Time. Check it out! | | |
Permission to Share
If you would like to share, please forward the Tips message in its entirety. You can share excerpts as well, with the following attribution:
Source: Rebecca Herold. October 2025 Privacy Professor Tips
www.privacysecuritybrainiacs.com.
NOTE: Permission for excerpts does not extend to images.
Privacy Notice & Communication Information
You are receiving this Privacy Professor Tips message as a result of:
1) subscribing through PrivacyGuidance.com or PrivacySecurityBrainiacs.com or
2) making a request directly to Rebecca Herold or
3) connecting with Rebecca Herold on LinkedIn.
When LinkedIn users invite Rebecca Herold to connect with them, she sends a direct message when accepting their invitation. That message states that in the spirit of networking and in support of the communications that are encouraged by LinkedIn, she will send those asking her to link with them her monthly Tips messages. If they do not want to receive the Tips messages, the new LinkedIn connections are invited to let Rebecca know by responding to that LinkedIn message or contacting her at rebeccaherold@rebeccaherold.com.
If you wish to unsubscribe, just click the SafeUnsubscribe link below.
| | | | |